Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "Multiple Vendors" — 2011 resultados ✕ Limpiar búsqueda
13,696
Total alertas
3097
Críticas
10327
Altas
8
Ransomware
1772
Esta semana
RSS
M Crítico vulnerabilidad
01/07/2026
[CVE-2026-34100] Guardian language-system passes the id GET parameter directly into an unsanitized SQL query in media…
Guardian language-system passes the id GET parameter directly into an unsanitized SQL query in media.php (line 17): SELECT id, filename, extension, type, duration, owner, private FROM files where id = '\".$_GET['id'].\"'. An authenticated attacker can perform error-based SQL injection to extract database contents.
M Crítico vulnerabilidad
01/07/2026
[CVE-2026-57517] Control Web Panel before 0.9.8.1225 contains a blind SQL injection vulnerability that allows unauthe…
Control Web Panel before 0.9.8.1225 contains a blind SQL injection vulnerability that allows unauthenticated remote attackers to execute arbitrary SQL queries by submitting unsanitized input through the userRes POST parameter at the user endpoint. Attackers can exploit MySQL root privileges obtained via the injection to write arbitrary files using INTO DUMPFILE, enabling deployment of a PHP webshe…
M Crítico vulnerabilidad
01/07/2026
[CVE-2026-24270] NVIDIA AIStore framework contains a vulnerability where an attacker could bypass authentication. A s…
NVIDIA AIStore framework contains a vulnerability where an attacker could bypass authentication. A successful exploit of this vulnerability might lead to denial of service, escalation of privileges, information disclosure, and data tampering.
M Crítico vulnerabilidad
01/07/2026
[CVE-2025-15646] HTML::Gumbo versions before 0.19 for Perl disclose heap memory via type confusion. Support for the …
HTML::Gumbo versions before 0.19 for Perl disclose heap memory via type confusion. Support for the element was added to libgumbo 0.10.0 in 2015, but the walk_tree function in lib/HTML/Gumbo.xs was not updated to support it. The element was treated as a text-node, where strlen() over-reads the heap block that the pointer addresses. Any caller that runs parse() with the default format =…
M Crítico vulnerabilidad
01/07/2026
[CVE-2025-23350] NVIDIA ConnectX and BlueField contain a vulnerability in the command interface where a local user wi…
NVIDIA ConnectX and BlueField contain a vulnerability in the command interface where a local user with virtual function (VF) access may cause a write out of bounds by crafted input. A successful exploit of this vulnerability may lead to arbitrary code execution on the device.
M Crítico vulnerabilidad
01/07/2026
[CVE-2025-23351] NVIDIA ConnectX and BlueField contain a vulnerability in the command interface where a local user wi…
NVIDIA ConnectX and BlueField contain a vulnerability in the command interface where a local user with virtual function (VF) access may cause a write out of bounds by crafted input. A successful exploit of this vulnerability may lead to arbitrary code execution on the device.
M Crítico vulnerabilidad
01/07/2026
[CVE-2026-23537] A vulnerability has been identified in the Feast Feature Server’s `/save-document` endpoint that all…
A vulnerability has been identified in the Feast Feature Server’s `/save-document` endpoint that allows an unauthenticated remote attacker to write arbitrary JSON files to the server's filesystem. Although the system attempts to restrict file locations, these protections can be bypassed, enabling an attacker to overwrite vital application configurations or startup scripts. Because this flaw requir…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
01/07/2026
[CVE-2026-57692] Incorrect Privilege Assignment vulnerability in LCweb PrivateContent allows Privilege Escalation. T…
Incorrect Privilege Assignment vulnerability in LCweb PrivateContent allows Privilege Escalation. This issue affects PrivateContent: from n/a through 9.9.2.
M Crítico vulnerabilidad
01/07/2026
[CVE-2026-10539] A Control-M/Server communication command does not sufficiently filter or sanitize user-supplied inpu…
A Control-M/Server communication command does not sufficiently filter or sanitize user-supplied input. Under certain conditions, this issue may allow an unauthenticated attacker to execute unauthorized commands on the affected server, potentially leading to compromise of the server.  This vulnerability affects Control-M/Server versions 9.0.20.x to 9.0.21.200 (included) and potentially earlier u…
M Crítico vulnerabilidad
01/07/2026
[CVE-2026-11387] The SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery plugin for …
The SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 3.9.5. This is due to the plugin not properly validating a user's identity prior to updating their details like reset the password of any user account, including administrators, and gain full a…
M Crítico vulnerabilidad
01/07/2026
[CVE-2026-6070] The WP-BusinessDirectory plugin for WordPress is vulnerable to Unauthenticated Arbitrary File Deleti…
The WP-BusinessDirectory plugin for WordPress is vulnerable to Unauthenticated Arbitrary File Deletion in versions up to and including 4.0.1. This is due to insufficient path validation in the remove() method of the JBusinessDirectoryControllerUpload class. The task=upload.remove endpoint is accessible without authentication via the plugin's frontend routing system. The _filename parameter is acce…
M Crítico vulnerabilidad
30/06/2026
[CVE-2026-56413] Storage Concentrator (SC & SCVM) contains a command injection vulnerability in the ms_service.pl ser…
Storage Concentrator (SC & SCVM) contains a command injection vulnerability in the ms_service.pl service, which listens on TCP port 9000 by default and accepts custom network packets to perform device actions. An unauthenticated remote attacker can send a specially crafted packet containing a malicious payload that is processed without adequate sanitization, resulting in arbitrary command executio…
M Crítico vulnerabilidad
30/06/2026
[CVE-2026-56415] Storage Concentrator (SC & SCVM) contains a command injection vulnerability within the debug.pl scri…
Storage Concentrator (SC & SCVM) contains a command injection vulnerability within the debug.pl script that is reachable without authentication. A remote attacker can submit a specially crafted HTTP request containing a malicious payload that is processed without adequate input sanitization, resulting in arbitrary command execution with root-level privileges on the underlying system.
M Crítico vulnerabilidad
30/06/2026
[CVE-2026-56700] Grav CMS before 2.0.0-beta.2 contains multiple code-execution vulnerabilities. Three unsafe unserial…
Grav CMS before 2.0.0-beta.2 contains multiple code-execution vulnerabilities. Three unsafe unserialize() calls - in Scheduler\JobQueue, Framework\Cache\Adapter\FileCache, and Session - deserialize untrusted data without restricting allowed classes, enabling PHP object injection and, via a gadget chain, arbitrary code execution where an attacker controls the serialized input. Additionally, Install…
M Crítico vulnerabilidad
30/06/2026
[CVE-2026-55721] Storage Concentrator (SC & SCVM) is vulnerable to SQL injection through cookie values processed by t…
Storage Concentrator (SC & SCVM) is vulnerable to SQL injection through cookie values processed by the login.pl and debug.pl scripts. The cookie value is incorporated directly into database queries without adequate sanitization, allowing an unauthenticated remote attacker to manipulate those queries and extract sensitive information from the underlying database, including session tokens, password …

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
30/06/2026
[CVE-2026-50110] Storage Concentrator (SC & SCVM) contains hardcoded credentials for numerous internal services embed…
Storage Concentrator (SC & SCVM) contains hardcoded credentials for numerous internal services embedded within a configuration file. While the credentials are stored in an encoded format, the encoding can be reversed to plaintext. The exposed credentials span a broad range of internal services, including database accounts, licensing, replication services, and third-party integrations, meaning succ…
M Crítico vulnerabilidad
30/06/2026
[CVE-2026-58449] txtai through 9.10.0, fixed in commit 11b32da, exposes an API /reindex endpoint whose function body …
txtai through 9.10.0, fixed in commit 11b32da, exposes an API /reindex endpoint whose function body parameter is resolved through txtai.util.Resolver, which performs __import__ and getattr on the caller-supplied dotted path with no allowlist. When the API is exposed with no TOKEN configured (authentication is opt-in, so all endpoints are unauthenticated) and the index is configured writable, a rem…
M Crítico vulnerabilidad
30/06/2026
[CVE-2026-50003] A malicious or compromised server can make a DCMTK client using bit-preserving C-GET storage mode wr…
A malicious or compromised server can make a DCMTK client using bit-preserving C-GET storage mode write files outside the chosen output directory, using both relative (../) paths and absolute paths.
M Crítico vulnerabilidad
30/06/2026
[CVE-2026-37106] An issue in DokuWiki 2025-05-14b "Librarian" 56.2 allows a remote attacker to create an account via …
An issue in DokuWiki 2025-05-14b "Librarian" 56.2 allows a remote attacker to create an account via the register function in inc/auth.php. NOTE: this is disputed by the Supplier because this is the intentional behavior when the product is configured for self-registration (a non-default feature). The supplier also notes that there is no configuration migration scenario that would result in the self…
M Crítico vulnerabilidad
30/06/2026
[CVE-2026-58138] Orkes Conductor 3.21.21 before 3.30.2 contains an unauthenticated remote code execution vulnerabilit…
Orkes Conductor 3.21.21 before 3.30.2 contains an unauthenticated remote code execution vulnerability that allows remote attackers to execute arbitrary OS commands by submitting inline workflow definitions containing malicious JavaScript or Python expressions to the workflow API endpoint prior to authentication. Attackers can exploit unsandboxed GraalVM evaluators configured with HostAccess.ALL or…